PT-2026-7619 · WordPress · Product Options/Price Calculation Formulas For Woocommerce – Uni Cpo

Stefan Jost

·

Published

2026-02-11

·

Updated

2026-02-11

·

CVE-2025-13391

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) versions through 4.9.60
Description The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress has a flaw that could allow unauthorized data loss. A missing capability check within the uni cpo remove file function permits unauthenticated attackers to delete arbitrary attachments or files stored in Dropbox, provided the file path is known.
Recommendations Update to a version beyond 4.9.60.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13391

Affected Products

Product Options/Price Calculation Formulas For Woocommerce – Uni Cpo